logo

New Response

« Return to the blog entry

You are replying to:

    • avatar
    • Patrick L
    • Posted on Fri 26 Sep 2008 06:27 AM

    I have one question - once the admin had realised their cookie had been compromised they could use a sign out link - eg: http://Host/DatabaseDirectory/DatabaseFileName?Logout

    shouldn't this be enough to end the session on the server and make the DomAuthSessId invalid?

Your Comments

Name:
E-mail:
(optional)
Website:
(optional)
Comment: